Skip to content

fix: Fix CVE-2026-35535#9

Merged
Zeno-sole merged 1 commit intomasterfrom
fix/CVE-2026-35535
Apr 15, 2026
Merged

fix: Fix CVE-2026-35535#9
Zeno-sole merged 1 commit intomasterfrom
fix/CVE-2026-35535

Conversation

@deepin-ci-robot
Copy link
Copy Markdown
Contributor

Fix CVE-2026-35535: exec_mailer: Set group as well as uid when running the mailer.

Also make a setuid(), setgid() or setgroups() failure fatal.

Upstream: sudo-project/sudo@3e474c2

@github-actions
Copy link
Copy Markdown

github-actions bot commented Apr 13, 2026

TAG Bot

TAG: 1.9.16p2-3deepin2
EXISTED: no
DISTRIBUTION: unstable

@Zeno-sole
Copy link
Copy Markdown

/integrate

@github-actions
Copy link
Copy Markdown

AutoIntegrationPr Bot
auto integrate with pr url: deepin-community/Repository-Integration#3821
PrNumber: 3821
PrBranch: auto-integration-24376449795

Comment thread debian/changelog Outdated
@@ -1,3 +1,10 @@
sudo (1.9.16p2-3deepin2) UNRELEASED; urgency=medium
Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

UNRELEASED

Comment thread debian/changelog
* Fix CVE-2026-35535: exec_mailer: Set group as well as uid when
running the mailer.

-- deepin-ci-robot <packages@deepin.org> Mon, 13 Apr 2026 21:24:10 +0800
Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Whom? Which LLM is used to generate this PR?

Copy link
Copy Markdown

@UTsweetyfish UTsweetyfish left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

git author and commiter should be human, and Co-Authored-By: should be adopted when the commit is generated by a LLM model.

- Set group as well as uid when running the mailer
- Make setuid(), setgid() or setgroups() failure fatal
- Add mailgid field to eventlog_config structure
- Update eventlog_set_mailuid() to eventlog_set_mailuser() with gid parameter

Upstream: https://www.sudo.ws/security/advisories/CVE-2026-35535/
@Zeno-sole
Copy link
Copy Markdown

/integrate

Copy link
Copy Markdown

@UTsweetyfish UTsweetyfish left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Co-Authored-By 无 AI 使用说明
d/changelog 未说明使用 AI

@deepin-ci-robot
Copy link
Copy Markdown
Contributor Author

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: Zeno-sole

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@Zeno-sole Zeno-sole merged commit d14b2a3 into master Apr 15, 2026
8 of 10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants